<< Prev Question Next Question >>

Question 14/21

An administrator is concerned that someone may be using unauthorized commands from cmd.exe. These commands are not considered suspicious or malicious, and there is no policy based around them.
Which page should the administrator use to find these commands?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (21q)
Question 1: An administrator is reviewing an alert about a known and req...
Question 2: A Carbon Black Cloud Endpoint Standard analyst is testing di...
Question 3: An administrator has updated a Threat Intelligence Report by...
Question 4: Review this result after executing a query in the Process Se...
Question 5: How long will Live Queries in Carbon Black Audit and Remedia...
Question 6: Review the following EDR query: (parent_name:powershell.exe ...
Question 7: An analyst navigates to the alerts page in Endpoint Standard...
Question 8: An analyst is investigating an alert within Enterprise EDR. ...
Question 9: An Enterprise EDR administrator is reviewing the Investigate...
Question 10: An administrator has configured a policy to run a standard b...
Question 11: Which enforcement level does not block unapproved files but ...
Question 12: Given the following query: SELECT hostname, cpu_type, cpu_br...
Question 13: Why would a sensor have a status of "Inactive"?...
Question 14: An administrator is concerned that someone may be using unau...
Question 15: A watchlist generates a false positive on the Triage Alerts ...
Question 16: Which statement filters data to only return rows where the p...
Question 17: An active compromise is detected on an endpoint. Due to curr...
Question 18: Which actions are available for Permissions?...
Question 19: An analyst has investigated multiple alerts on a number of H...
Question 20: Refer to the exhibit, noting the circled red dot: (Exhibit) ...
Question 21: A process is writing numerous interesting files that never a...